In-depth commentaries

Blinded by the LED: smart glasses, GDPR, and the illusion of hardware indicators

Smart glasses are attracting much attention these days. Already significant sales seem to pale in comparison to the explosion of social commentary on them, just as the segment of camera-enabled wearables is growing also in terms of form factors and devices, with AI-powered pins, portable speakers and even headphones around the corner. A few months […]

Read Analysis →

Who interprets the GDPR? EDPB (soft) law and the case for reform

The European Data Protection Board (EDPB) can adopt various legal instruments, including Guidelines and Opinions, that are formally non-binding. Yet if supervisory authorities rarely (if ever) depart from them, controllers and processors structure their compliance efforts around them, and data subjects rely upon them in complaints and litigation, perhaps that formal status deserves a second […]

Read Analysis →

EDPB Guidelines on Anonymisation: where unforeseeable is reasonable?

How the EDPB’s attempt to rewrite key data protection concepts creates more issues than it solves Through its Guidelines 02/2026 on Anonymisation of 7 July 2026, the European Data Protection Board seems at first glance to have done the honourable thing: admitting defeat and moving on. But behind the apparent recognition of the relative nature […]

Read Analysis →

Incidental processing and GDPR: from bystanders to spontaneous notes, do data protection rules apply?

Another week, another product announcement from someone involving AI in your pocket, on your wrist, in front of your eyes. I have met people whose lives have literally been transformed as a result of some of these tools, such as an individual who is suddenly able to use a camera in glasses to film his […]

Read Analysis →

DMA & anonymisation: regulatory risks of under-anonymisation

How solid is your anonymisation? Is “good enough + contractual prohibition to re-identify” really sufficient? The Commission’s DMA team seems to think so, though its own idea of “good enough” relies on magic personal data scrubbers. Perhaps the Commission’s DMA team should read up again on GDPR case law on “personal data” (Breyer, Scania, SRB […]

Read Analysis →

Anonymisation of personal data: compliance vs utility, regulators vs the law

The clear repudiation of an “absolute” concept of personal data has thrown a sharp focus on the process of pseudonymisation in the world of data protection. Through its SRB judgment of 4 September 2025, the Court of Justice of the European Union (CJEU) made it clear that personal data that has undergone pseudonymisation can be […]

Read Analysis →

Making the GDPR realistic? Authorities only want that in part

[This is a translation of an op-ed in French that was published in the French journal Revue Politique on SRB and the Digital Omnibus, plus the newest EDPB & EDPS Joint Opinion on the topic. The original in French can be found on the Revue Politique website. + The banner image is a jest – […]

Read Analysis →

Pseudonymisation & “means reasonably likely to be used” for identification: when does data become personal?

As I was in a meeting when the European Data Protection Board opened registration for its pseudonymisation stakeholder event of 12 December 2025, I missed the short (approx. 1h) registration window and they placed me on a waiting list instead – a pity given my frequent interventions on the EU Court of Justice’s SRB judgment […]

Read Analysis →

DMA-GDPR Guidelines: formal response to public consultation

When I pointed out issues with the DMA-GDPR Guidelines & resulting risks for *all* controllers (not just gatekeepers), the EDPB’s Gwendal Le Grand said something to the effect of “Don’t just post about it, submit a response”. So here we go, a copy of the response submitted yesterday to the public consultation by the Commission […]

Read Analysis →

When is data no longer personal? And what are the implications?

The ruling of the Court of Justice of the European Union (CJEU) of yesterday, 4 September 2025, in the EDPS v SRB case is significant – never mind the naysayers. It is the first time that the CJUE has clearly, explicitly said that if a dataset initially contains personal data but is pseudonymised, and that […]

Read Analysis →